Lucene search

K
freebsdFreeBSD597E2BEE-68EA-11D9-A9E7-0001020EED82
HistoryDec 21, 2004 - 12:00 a.m.

ImageMagick -- PSD handler heap overflow vulnerability

2004-12-2100:00:00
vuxml.freebsd.org
24

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.108 Low

EPSS

Percentile

95.1%

An iDEFENSE Security Advisory reports:

Remote exploitation of a buffer overflow vulnerability in
The ImageMagick’s Project’s ImageMagick PSD image-decoding
module could allow an attacker to execute arbitrary
code.
Exploitation may allow attackers to run arbitrary code on
a victim’s computer if the victim opens a specially
formatted image. Such images could be delivered by e-mail
or HTML, in some cases, and would likely not raise
suspicion on the victim’s part. Exploitation is also
possible when a web-based application uses ImageMagick to
process user-uploaded image files.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchimagemagick< 6.1.8.8UNKNOWN
FreeBSDanynoarchimagemagick-nox11< 6.1.8.8UNKNOWN

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.108 Low

EPSS

Percentile

95.1%